PT-2026-60258 · Pypi · Strands-Agents-Tools

CVE-2026-15746

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions strands-agents-tools versions prior to 0.7.0
Description A server-side request forgery (SSRF) issue exists in the elasticsearch memory tool of the strands-agents-tools package. The tool exposes connection parameters es url, cloud id, and api key as fields controllable by the large language model (LLM) via the tool schema. If the api key parameter is omitted, the tool uses the operator's ELASTICSEARCH API KEY environment variable and sends it to the host specified by the LLM. A crafted prompt can force the tool to connect to an external server, disclosing the operator's Elasticsearch API key within the Authorization header.
Recommendations Upgrade to version 0.7.0 or later. Rotate the ELASTICSEARCH API KEY as a precautionary measure.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15746
GHSA-PPCF-FPR3-X46V

Affected Products

Strands-Agents-Tools